National Information Security Policy and Guidelines | Ministry of Home Affairs 8. Information security organization overview 8.1. Security division 8.1.1. Role of Chief Information Security Officer (CISO): The responsibility of security management should be entrusted to the “Security Division” under the charge of the Chief Information Security Officer (CISO). Its role cuts across the traditionally defined boundaries of IT and covers all the horizontal and vertical functions of an organization. CISO’s role is detailed below: 8.1.1.1. Design, implement, monitor and govern an organization-wide information security program 8.1.1.2. Ensure information security risk assessments and audits are performed as necessary. Oversee risk assessment exercise to understand the threats to key information assets, analyze risks with the concerned divisions of the organization 8.1.1.3. Design information security related policies, procedures and processes to ensure confidentiality, integrity, availability of classified information while establishing accountability, authorization and non- repudiation of actions over information 8.1.1.4. Review policies, procedures and standard operating procedures 8.1.1.5. Work on positioning of security division, so as to make it more effective 8.1.1.6. Devise programs for capacity building and oversee information security training and development of personnel. Additionally, the CISO should establishing mechanisms for information security awareness in the organization 8.1.1.7. Liaison with relevant agencies to gather intelligence about prevailing threats and best practices 8.1.2. Reporting structure: The Chief Information Security Officer (CISO) or equivalent will report directly to the Secretary concerned of the respective Ministry/ Department 8.2. Information security division & roles (Refer “Cyber Security Policy for Government of India” ver 2.0 released 30th August, 2010) 8.2.1. The following roles are required based on the fact that each Ministry/ Department/ Organization is located in one of more location/ Bhawan and each location/ Bhawan has one or more Ministries / Departments / Organizations. 8.2.1.1. National Information Security Officer (NISO): Responsible for cyber security of all Ministries/ Departments of Government of India 8.2.1.2. Chief Information Security Officer (CISO): Responsible for cyber security in the respective Ministry/ Department. This role is to be designated by the respective Ministry/ Department 8.2.1.3. Cyber Security Administrator (CSA): Responsible for technical functions, related to cyber security for Ministries/ Departments 8.2.1.4. Information Security Officer (ISO): Responsible for administrative functions related to security for every location of the Ministry/ Department. This role is to be designated by the Ministry/ Department for each location of the Ministry/ Department NISPG - Version 5.0 Restricted Page 27

Select target paragraph3